Attackers are exploiting a critical (CVSS 9.1) authentication bypass vulnerability, CVE-2026-16232, in Check Point Security Management servers, allowing unauthenticated attackers to obtain admin login tokens and fully compromise firewall policy via SmartConsole.
Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the management servers that push policy to Check Point security gateways (i.e., firewalls). “An unauthenticated attacker can obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security configuration,” the company said. The vulnerability is being exploited, they confirmed, and a “handful” … More → The post Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232) appeared first on Help Net Security .